Skip to content
This repository was archived by the owner on Mar 6, 2026. It is now read-only.
This repository was archived by the owner on Mar 6, 2026. It is now read-only.

Dependency Sources #56

Description

@c0rydoras

Goal

  • Allow multiple dependency_sources (packages) e.g package-a/yarn.lock, package-b/yarn.lock
  • Assign maintainers per source

Implementation

  • Projects have a m2m of DependencySource
  • Projects do no longer have versioned_dependencies or maintainers
  • DependencySource has versions which is an m2m for Version
  • Maintainers now have a source field that replaces the project field
class Maintainer
    ...
    source = models.ForeignKey(
        DependencySource, on_delete=models.CASCADE, related_name="maintainers"
    )
    ...
  • Due to how lockfiles are implemented we use their name and create a source from it:
class Tracker:
    # this would also be adjusted further
    ...
    def _get_lockfile(self, root, file):
        file_path = path.join(root, file)
        rel_file_path = path.relpath(file_path, self.local_path)
        with open(file_path, "r") as file_content:
            return {"name": rel_file_path, "data": file_content.read()} # e.g. {"name": "./api/poetry.lock", "data": "..."}

    @property
    def lockfiles(self):
        if not self.has_local_copy:
            raise RepoDoesNotExist(
                f"Unable to retrieve lockfiles for {self.project.repo} because it is not saved locally."
            )

        lockfile_list = []
        for root, _, files in walk(self.local_path):
            if ".git" in root:
                continue

            lockfile_list.extend([self._get_lockfile(root, file) for file in files])

        return lockfile_list
     ...
  • Adjust Parser to set versions on sources instead of versioned_dependencies on the project
  • Adjust views and serializers
  • Adjust tests
  • Write tests

Further implementation

Activity

  1. added
    backendThis issue or pull request is backend related
    featureThis issue or pull request discusses a feature
    breakingThis issue or pull request discusses something breaking
    on Aug 14, 2023
  2. self-assigned this
    on Aug 14, 2023
  3. added this to the Outdated v1 milestone on Aug 14, 2023
  4. moved this to Getting planned in Outdated v1on Aug 14, 2023
  5. moved this from Getting planned to Todo in Outdated v1on Sep 1, 2023
  6. removed this from the Outdated v1 milestone on Feb 9, 2024
  7. linked a pull request that will close this issueApi/dependency sources #187on Mar 5, 2024
  8. moved this to In Progress in Outdated v1on Mar 15, 2024
  9. linked a pull request that will close this issuefeat!: dependency-sources #299on Mar 15, 2024
  10. moved this from In Progress to Waiting for review in Outdated v1on Mar 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

backendThis issue or pull request is backend relatedbreakingThis issue or pull request discusses something breakingfeatureThis issue or pull request discusses a feature

Type

No type

Projects

  • Status
    Waiting for review

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions